CyberRota Analysis
AI-GeneratedIn Nmap Scanner versions prior to 3.0.15, users with permissions to edit, create, or execute playbooks in Splunk SOAR can exploit a misclassification of the scan network action as read-only, allowing unauthorized command execution or modifications on target systems via Nmap Scripting Engine scripts. This vulnerability poses a risk to environments utilizing Splunk SOAR for network scanning and automation. Organizations using these versions should prioritize patching to mitigate potential security breaches.
Original NVD Description
In Nmap Scanner versions below 3.0.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could run the scan network action in a Safe Mode playbook while that action is listed as read-only, which could allow for command execution or other changes on a target system through Nmap Scripting Engine scripts. The vulnerability is possible because the Nmap Scanner connector action manifest classifies the scan network action as read-only even though the action accepts script parameters that can perform write operations. For more information see Manage settings for a playbook in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-cloud/build-playbooks/manage-playbooks-and-playbook-settings/manage-settings-for-a-playbook-in-splunk-soar-cloud) in the Splunk documentation.